Microsoft Office Ltsc For Mac 2021 vulnerabilities
324 known vulnerabilities affecting microsoft/microsoft_office_ltsc_for_mac_2021.
Total CVEs
324
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH274MEDIUM39LOW9
Vulnerabilities
Page 1 of 17
CVE-2021-42292P1HIGHCVSS 7.8KEV≥ 16.0.1, < 16.55.211114002021-11-10
CVE-2021-42292 [HIGH] CVE-2021-42292: Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2026-21514P1HIGHCVSS 7.8KEV≥ 16.0.1, < 16.106.260208212026-02-10
CVE-2026-21514 [HIGH] CWE-807 CVE-2026-21514: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoC≥ 16.0.1, < 16.70.230212012023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2025-47165P1HIGHCVSS 7.8ExploitedPoC≥ 16.0.1, < 16.98.250608242025-06-10
CVE-2025-47165 [HIGH] CWE-416 CVE-2025-47165: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-47175P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.98.250608242025-06-10
CVE-2025-47175 [HIGH] CWE-416 CVE-2025-47175: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-27751P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.96.250413262025-04-08
CVE-2025-27751 [HIGH] CWE-416 CVE-2025-27751: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-60724P2CRITICALCVSS 9.8≥ 16.0.1, < 16.103.251109222025-11-11
CVE-2025-60724 [CRITICAL] CWE-122 CVE-2025-60724: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-23399P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.71.230312002023-03-14
CVE-2023-23399 [HIGH] CWE-125 CVE-2023-23399: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-28285P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.72.230409002023-04-11
CVE-2023-28285 [HIGH] CWE-416 CVE-2023-28285: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-28311P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.72.230409002023-04-11
CVE-2023-28311 [HIGH] CWE-122 CVE-2023-28311: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2023-36041P3HIGHCVSS 7.8≥ 16.0.1, < 16.79.231110192023-11-14
CVE-2023-36041 [HIGH] CWE-416 CVE-2023-36041: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-33146P3HIGHCVSS 7.8PoC≥ 16.0.1, < 16.74.230611002023-06-14
CVE-2023-33146 [HIGH] CWE-122 CVE-2023-33146: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2023-32029P3HIGHCVSS 7.8≥ 16.0.1, < 16.74.230611002023-06-14
CVE-2023-32029 [HIGH] CWE-125 CVE-2023-32029: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-33133P3HIGHCVSS 7.8≥ 16.0.1, < 16.74.230611002023-06-14
CVE-2023-33133 [HIGH] CWE-122 CVE-2023-33133: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2026-40364P3HIGHCVSS 8.4≥ 16.0.1, < 16.109.260510192026-05-12
CVE-2026-40364 [HIGH] CWE-122 CVE-2026-40364: Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50387P3HIGHCVSS 7.8≥ 16.0.1, < 16.111.260712152026-07-14
CVE-2026-50387 [HIGH] CWE-121 CVE-2026-50387: Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges local
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40361P3HIGHCVSS 8.4≥ 16.0.1, < 16.109.260510192026-05-12
CVE-2026-40361 [HIGH] CWE-416 CVE-2026-40361: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-20953P3HIGHCVSS 8.4≥ 16.0.1, < 16.105.260110182026-01-13
CVE-2026-20953 [HIGH] CWE-416 CVE-2026-20953: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40363P3HIGHCVSS 8.4≥ 16.0.1, < 16.109.260510192026-05-12
CVE-2026-40363 [HIGH] CWE-122 CVE-2026-40363: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40358P3HIGHCVSS 8.4≥ 16.0.1, < 16.109.260510192026-05-12
CVE-2026-40358 [HIGH] CWE-416 CVE-2026-40358: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
1 / 17Next →